ExtraHop named a leader in the Gartner® Magic Quadrant™ for Network Detection and Response

Search
  • Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

External Dharma Ransomware File Transfer

Risk Factors

Dharma is a popular ransomware family. Deploying Dharma requires skill that depends on the source and destination. The impact of ransomware on a business can be devastating, especially if sensitive or business-critical data is lost through encryption, or costly if a high ransom is paid.

The system might change the risk score for this detection.

Category

Command-and-Control

Decryptions

TLS Decryption
Detection diagram
Next in Command-and-Control: External EICAR Test File Transfer

Background

Dharma encrypts files and demands payment for the decryption key, similar to other ransomware families. Attackers often transfer malware from an external system into a compromised environment through a command-and-control channel or common protocol.

Mitigation Options

Monitor and investigate unusual activity to minimize potential damage

Configure host-based security tools to quarantine the host or otherwise prevent the file from executing

Filter ingress traffic at the network perimeter

MITRE ATT&CK ID

Associated content

Announcing The Forrester Wave™: Network Analysis And Visibility Solutions, Q4 2025

Network analysis and visibility solutions remain underrepresented in enterprises. Find out why in this preview of a new Wave report.

Report

ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response — ExtraHop

ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response

News

Detections

Visit this resource for more information.

Docs

The 2025 ExtraHop Global Threat Landscape Report: The Alarming Reality of Threat Actor Dwell Time and Deeper Network Access — ExtraHop

This analysis exposes the critical link between an organization's lack of internal visibility and the escalating cost of compromise, demanding an urgent re-evaluation of how core business assets are protected.

Blog

ExtraHop RevealX MITRE ATT&CK Coverage 2024 — ExtraHop

Learn why you need to be wary of the claims certain network detection and response providers make about their coverage against the MITRE ATT&CK framework.

Blog

MITRE ATT&CK - Network Detection & Response with RevealX — ExtraHop

Learn how NDR from RevealX helps security teams detect and investigate more adversary TTPs in the MITRE ATT&CK framework than rule-based tools.

External
Periodic Table of Use Cases

What else can RevealX do for you?